We have ~250 Windows 2008 or 2008 R2 servers that we have purchased Extended Support.
Three of the Windows 2008 servers revert the updates during the reboot after the updates are installed.
Listed below is the slmgr /dlv output for KMS key for the OS for one of the servers that the updates revert.
Description: Windows Operating System - Windows Server(R), VOLUME_KMSCLIENT chan
nel
Activation ID: ad2542d4-9154-4c6d-8a44-30f11ee96989
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 92573-00152-082-250011-03-1033-6001.0000-1792015
Installation ID: 006893183914298802914483410411175182966594596665924142
Partial Product Key: BFGM2
License Status: Licensed
Volume activation expiration: 253140 minute(s) (175 day(s))
Key Management Service client information
Client Machine ID (CMID): 43a102e7-bcba-4295-857e-d38340481b02
KMS machine name from DNS: GHKMASWP01.dot.missouri:1688
KMS machine extended PID: 06401-00206-551-429307-03-1033-9600.0000-2762019
Activation interval: 120 minutes
Renewal interval: 10080 minutes
Listed below is the slmgr /dlv output for the Extended Support MAK Key
Software licensing service version: 6.0.6002.18005
Name: Windows Server(R), Server-ESU-Year1 add-on for ServerDatacenter,ServerData
centerCore,ServerDatacenterV,ServerDatacenterVCore,ServerStandard,ServerStandard
Core,ServerStandardV,ServerStandardVCore,ServerEnterprise,ServerEnterpriseCore,S
erverEnterpriseV,ServerEnterpriseVCore
Description: Windows Operating System - Windows Server(R), VOLUME_MAK channel
Activation ID: 553673ed-6ddf-419c-a153-b760283472fd
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 55041-00168-888-659706-03-1033-6003.0000-0912020
Installation ID: 021870482125098946196876729856817703223542942593547823
Processor Certificate URL:
http://go.microsoft.com/fwlink/?LinkID=48189
Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=48190
Use License URL: http://go.microsoft.com/fwlink/?LinkID=48192
Product Key Certificate URL:
http://go.microsoft.com/fwlink/?LinkID=48191
Partial Product Key: 76F4X
License Status: Licensed
I have checked that the following perquisite KB's have been installed:
Window 2008
KB4474419 - SHA-2 support
KB4493730 - SSU
KB4536953 - SSU
KB4538484 - ESU
As I said before, the updates install but during the reboot to apply the updates, the updates revert back.
Listed below is an excerpt of the CBS Log showing the error:
2020-05-05 16:54:52, Info CSI 00000001 ESU: Product = 7.
2020-05-05 16:54:52, Info CSI 00000002 ESU: Failed to Get PKey Info c004f014 [Error,Facility=FACILITY_ITF,Code=61460 (0xf014)].
2020-05-05 16:54:53, Info CSI 00000003 ESU: Is IMDS check needed:TRUE
2020-05-05 16:54:53, Info CSI 00000004 ESU: not eligible HRESULT_FROM_WIN32(1633).
2020-05-05 16:54:53, Info CSI 0000000a@2020/5/5:21:54:53.102 CSI Advanced installer perf trace:
CSIPERF:AIDONE;{9e5ebca3-ef4e-4968-bdd1-d8049229d686};Microsoft-Windows-SLC-Component-ExtendedSecurityUpdatesAI, Version = 6.0.6003.20789, pA = PROCESSOR_ARCHITECTURE_INTEL (0), Culture neutral, VersionScope = 1 nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35},
Type neutral, TypeName neutral, PublicKey neutral;153140
2020-05-05 16:54:53, Info CSI 0000000b Performing 1 operations; 1 are not lock/unlock and follow:
LockComponentPath (10): flags: 0 comp: {l:16 b:70cc9bce2723d60105000000b0040005} pathid: {l:16 b:70cc9bce2723d60106000000b0040005} path: [l:234{117}]"\SystemRoot\WinSxS\x86_microsoft.windows.s..ation.badcomponents_31bf3856ad364e35_6.0.6001.18000_none_3891bf6bc31ec194"
pid: 4b0 starttime: 132331892218721370 (0x01d62327a426f45a)
2020-05-05 16:54:53, Error CSI 0000000c (F) Failed execution of queue item Installer: Extended Security Updates Advanced Installer ({9e5ebca3-ef4e-4968-bdd1-d8049229d686})
with HRESULT HRESULT_FROM_WIN32(1633). Failure will be ignored: The failure was encountered during rollback; installer is reliable (2)[gle=0x80004005]
All the Web searches I did on
ESU: Failed to Get PKey Info c004f014 [Error,Facility=FACILITY_ITF,Code=61460 (0xf014)].
ESU: not eligible HRESULT_FROM_WIN32(1633).
(F) Failed execution of queue item Installer: Extended Security Updates Advanced Installer ({9e5ebca3-ef4e-4968-bdd1-d8049229d686}) with HRESULT HRESULT_FROM_WIN32(1633). Failure will be ignored: The failure was encountered during rollback; installer
is reliable (2)[gle=0x80004005]
have led me to articles on how to register the EUS MAK Key.
It looks to me that during the install after the reboot, the Installed does not recognize the servers as eligible for Extended updates and reverts the updates.
This does not make sense to me because the SLMGR /dlv command shows the MAK is Licensed.
All help in resolving this issue would be greatly appreciated.
Note, our servers do not have access to the Internet but we do have a Microsoft Proxy Certificate server in place. These servers are configured to use it.